What's changed: Initial version
4.2System Audit and Service Management
Learn the flow of system audit, in which an independent third party evaluates information systems, and its relationship to internal control; ITIL and the SLA (service level agreement) that underpin the continuous operation of IT services; availability management, which keeps systems running, and capacity management, which prepares for future load; and how audit evidence (logs) is handled as the basis for an audit.
Information security does not end once controls are put in place—it requires an independent party to confirm those controls actually work, and continuous maintenance through day-to-day operations. Here we cover two pillars: system audit, the mechanism for evaluation, and service management, which sustains operations.
4.2.1System audit flow and internal control
- System audit is an activity in which an independent system auditor verifies whether risk management and internal control related to information systems are functioning effectively, following the flow audit planning -> preliminary survey -> main survey -> evaluation/conclusion -> reporting -> follow-up. Independence from the audited department is the premise for its credibility.
- Internal control is the set of mechanisms (segregation of duties, approval processes, monitoring, etc.) that management itself establishes and operates to ensure business is conducted properly. A system audit is the activity that checks, from outside (or an independent internal audit function), whether internal control is functioning effectively—a distinct role from internal control itself.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

